explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR — what people are asking
  • What exactly did Sakana AI launch?
  • What do the CyberGym and CTI-REALM scores actually measure?
  • How does Fugu-Cyber's orchestration architecture work?
  • Sakana's “reality check”: why Mythos access does not fix enterprise security
  • Why the verification harness and human-in-the-loop matter more than raw output
  • Why the Japan and AI-sovereignty angle is central
  • Is Fugu-Cyber safer than an unrestricted cyber model?
  • What does Fugu-Cyber cost, and what does “Token Plan” mean?
  • Fugu-Cyber vs a single frontier model: which approach wins?
  • How does this answer the July 2026 cyber-guardrails debate?
  • Who should apply for Fugu-Cyber?
  • Bottom line
  • Related on explainx.ai
← Back to blog

explainx / blog

Fugu-Cyber: Sakana AI Orchestrates Frontier Models for Cyber Defense

Sakana AI's Fugu-Cyber scores 86.9% on CyberGym and 72.1% on CTI-REALM. Here is how its orchestration, access gating, and pricing work.

Jul 21, 2026·17 min read·Yash Thakker
Sakana AIFugu-CyberCybersecurityMulti-Agent SystemsAI SovereigntyOrchestration
go deep
Fugu-Cyber: Sakana AI Orchestrates Frontier Models for Cyber Defense

On July 21, 2026, Tokyo-based Sakana AI launched Fugu-Cyber, a security-specialized update to its Fugu multi-agent orchestration system. The headline is 86.9% on CyberGym and 72.1% on CTI-REALM, which Sakana says is state of the art and comparable to cyber-focused frontier systems such as GPT-5.5-Cyber and Mythos-Preview.

The more consequential claim is not that another model can find bugs. Sakana argues that a raw frontier API is not an enterprise security program. Fugu-Cyber packages multiple agents behind one endpoint, while Sakana's Applied Enterprise team builds the verification harnesses, proprietary-code integrations, and human review loops needed to turn candidate findings into defensible production decisions.

That pitch arrives directly inside July's cyber-guardrails debate: defenders say hosted models refuse legitimate exploit-adjacent work, while vendors point to real dual-use risk. Fugu-Cyber's answer is neither an unrestricted general API nor a blanket refusal. It is gated capability inside a verification workflow.

TL;DR — what people are asking

QuestionAnswer as of July 21, 2026
What is Fugu-Cyber?A cyber-specialized multi-agent orchestration model delivered through one API endpoint
What are the benchmarks?86.9% CyberGym · 72.1% CTI-REALM, both reported by Sakana
How do I access it?Submit an intended-use application plus verified contact details; Sakana manually reviews access
Is it offensive-capable?Cyber capability is dual-use, but the product is defense-focused and its updated AUP prohibits offensive misuse
How is it different from one frontier model?It dynamically delegates across specialized agents, verifies work, and synthesizes one response instead of relying on one model/provider
What plan and price?Token Plan / pay-as-you-go only; fugu-cyber-v1.0 starts at $6/M input, $36/M output, $0.60/M cached input
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.


What exactly did Sakana AI launch?

Fugu-Cyber is a new model in the existing Fugu API rather than a separate security application or downloadable open-weight checkpoint. According to Sakana's official July 21 announcement, it is “purpose-built for the complexities of modern cyber defense” and is available as a new endpoint at sakana.ai/fugu.

The product now has a three-model lineup:

ModelPrimary optimizationBest fitAccess
FuguBalance of performance and latencyEveryday coding, review, chat, and interactive workSubscription or pay-as-you-go
Fugu UltraMaximum quality through deeper orchestrationResearch, difficult engineering, long multi-step tasksSubscription or pay-as-you-go
Fugu CyberSecurity reasoning and verificationVulnerability analysis, threat investigation, detection workflowsApproved Token Plan / pay-as-you-go access

All three use one OpenAI-compatible API, so switching models does not require replacing an integration. The original Fugu supports both Chat Completions and Responses endpoints; the Fugu technical report and product documentation describe the orchestration layer behind that interface.

Fugu-Cyber is not presented as a self-hosted cyber model. It is a managed system whose selected underlying agents and routing decisions remain proprietary. That distinction matters for SOC teams with strict data-residency, provider, or audit requirements: the endpoint is simple, but the internal execution graph is deliberately opaque.


What do the CyberGym and CTI-REALM scores actually measure?

Security benchmarks are easy to flatten into one leaderboard number. These two measure different parts of a blue team's workflow.

BenchmarkFugu-CyberWhat it testsWhy a defender cares
CyberGym86.9%Analyze complex codebases and verify real-world vulnerabilitiesAppSec teams need evidence that a reported weakness is reachable and reproducible, not another static-analysis alert
CTI-REALM72.1%Convert raw threat-intelligence reports into working detection rulesSOC teams need executable detections from prose reports quickly enough to catch an active campaign

CyberGym: can the system verify a real vulnerability?

A vulnerability description is not the same as a verified issue in your deployment. The agent must navigate a codebase, understand control and data flow, identify the relevant build or runtime conditions, and determine whether the suspected flaw actually triggers.

That is why 86.9% on CyberGym is operationally interesting. A high score suggests Fugu-Cyber can do more than name insecure patterns. It can work through the code-level evidence needed for triage. This is adjacent to the capability Anthropic highlighted in Mythos Preview and Project Glasswing, where model-driven vulnerability research raised both defensive opportunity and dual-use concern.

It still does not tell a CISO the false-positive rate on a private monorepo, whether the system understands custom deployment controls, or how much human time each verified finding consumes. Those questions require an evaluation on the organization's own software and harness.

CTI-REALM: can it turn reports into detections?

Threat intelligence often arrives as prose: infrastructure indicators, attacker behavior, malware techniques, and fragmented observations. The useful SOC artifact is a working rule—such as a query or detection that can run against the organization's telemetry.

Fugu-Cyber's 72.1% CTI-REALM score targets this translation step. That matters because hand-converting every advisory into environment-specific detections is slow, and detection latency creates exposure. It also exposes the hard part: a syntactically valid rule can still be noisy, miss local log schemas, or fail against production data.

How strong is “comparable to GPT-5.5-Cyber and Mythos-Preview”?

Sakana describes both results as state of the art and says they are comparable to GPT-5.5-Cyber and Mythos-Preview. Treat that wording precisely:

  • The 86.9% and 72.1% figures are self-reported by Sakana.
  • The comparison methodology and model configurations matter.
  • Benchmark parity does not establish equal exploit-development capability, production reliability, latency, or cost.
  • No independent explainx.ai reproduction was available at publication time.

The original Fugu launch already showed why this distinction matters. Its published engineering scores were impressive, while early creative-coding tests exposed latency and real-world quality gaps. CyberGym and CTI-REALM are better aligned with Fugu-Cyber's intended work than shader tests, but buyers should still benchmark their own repositories and telemetry.


How does Fugu-Cyber's orchestration architecture work?

From the caller's perspective, Fugu-Cyber behaves like one model:

  1. A client sends one request to the Sakana API.
  2. The orchestrator decomposes the multi-step security task.
  3. It selects and coordinates specialized agents from a model pool.
  4. Agents analyze, challenge, or verify intermediate work.
  5. The system synthesizes one response through the original endpoint.

This is more than a one-shot router that picks “best coding model” or “best reasoning model.” The Fugu family is built on two ICLR 2026 research lines:

  • TRINITY evolves a compact coordinator that delegates roles to multiple LLMs turn by turn.
  • Conductor uses reinforcement learning to generate agent-to-agent communication structures and targeted instructions.

The Sakana Fugu technical report, arXiv:2606.21228, says the broader pool includes Claude Opus 4.8, Gemini 3.1 Pro, GPT-5.5, undisclosed open models, and the orchestrator itself as a possible recursive worker. Fugu Ultra can construct workflows of up to five steps; the report also describes adaptive memory needed to preserve model selection, communication topology, and function-call ownership across a multi-agent interaction.

That research lineage distinguishes Fugu from a hand-written chain of prompts. The coordinator is trained to decide how agents collaborate. It also makes the system harder to inspect: Sakana does not expose which underlying models handled a specific request.


Sakana's “reality check”: why Mythos access does not fix enterprise security

Sakana's launch post explicitly pushes back on cyber fearmongering—the idea that granting a company access to a powerful cyber model instantly transforms its security posture.

The company points to a July Nikkei Digital Governance report on the operational gap facing Japanese enterprises. Major financial institutions may understand the strategic significance of Mythos-class systems, yet access alone does not create:

  • engineers who know the proprietary codebase and architecture;
  • security specialists who can distinguish reachability from theoretical weakness;
  • safe access to source, build systems, logs, and production context;
  • verification infrastructure that can reproduce a finding;
  • a change-controlled path from evidence to patch and retest.

Sakana summarizes the thesis cleanly: a highly capable API is an important piece of the puzzle, not the entire solution.

This is not a reason to dismiss frontier cyber capability. It is a reason to locate the bottleneck correctly. A model may produce thousands of plausible findings faster than a security organization can validate them. Without operational integration, more model capability can create a larger triage queue rather than a safer system.

The same issue appears in Anthropic's Project Glasswing vulnerability volume: discovery scales faster than traditional disclosure, patching, and human review. Fugu-Cyber is Sakana's attempt to move verification into the product architecture rather than treating it as an afterthought.


Why the verification harness and human-in-the-loop matter more than raw output

Sakana says raw models “will inevitably generate false positives” and struggle with live production nuance without the right harness. The proposed enterprise workflow is therefore:

frontier reasoning → cyber-specialized sub-agent verification → human review → patch proposal → retest

The order matters. A patch should not be proposed merely because one model inferred a possible vulnerability. Specialized agents first need to test whether the issue triggers in the real environment; a qualified human then judges scope, impact, and remediation risk.

For vulnerability work, a credible harness should capture at least:

StageEvidence required
Candidate discoveryFile, code path, preconditions, affected versions
Reachability analysisWhether untrusted input can reach the vulnerable operation
ReproductionIsolated test, crash, sanitizer output, or safe proof of behavior
Environment checkDeployment flags, mitigations, identity boundaries, network controls
Patch reviewRegression risk, compatibility, and whether the root cause is removed
RetestOriginal trigger fails safely; expected behavior still passes

For detection engineering, the equivalent loop validates a generated rule against representative telemetry, measures false positives, checks schema compatibility, and runs the rule in shadow mode before enforcement.

This is established agent-harness engineering applied to a high-consequence domain. The model supplies reasoning; tools supply runtime evidence; sub-agents challenge assumptions; humans own authorization and production change.

Sakana says its Applied Enterprise team is working with major Japanese institutions on these specialized harnesses, including automated vulnerability verification and downstream tasks. The announcement does not name customers, publish deployment metrics, or quantify false-positive reduction, so those claims remain vendor-described enterprise work rather than independently auditable case studies.


Why the Japan and AI-sovereignty angle is central

Sakana AI is based in Tokyo, and Fugu-Cyber is framed around the constraints of Japanese institutions—not as a generic US model wrapper.

Japan's banks, critical infrastructure operators, and large enterprises face three linked problems:

  1. Frontier dependence: The strongest cyber reasoning may come from a small number of foreign providers.
  2. Local context: Proprietary Japanese systems, documentation, regulatory processes, and institutional knowledge do not arrive with an API key.
  3. Access risk: Export controls or provider policy can change who may use a model and for what purpose.

The original Fugu was pitched as a hedge against that third risk. A swappable agent pool avoids making one vendor the permanent point of failure. The broader Asian response to the Mythos access gap showed the geopolitical split: some labs pursue open weights, others build sovereign domestic stacks, and Sakana coordinates multiple frontier providers behind a Japanese enterprise layer.

Fugu-Cyber adds a more grounded definition of AI sovereignty. It is not simply “the model runs in Japan” or “the API vendor is Japanese.” It is the ability to combine multiple models, local security expertise, proprietary organizational context, and verification processes without letting any single foreign model determine the entire defensive capability.

There is still dependency underneath the abstraction. Fugu's pool includes closed US models, and customers cannot see the per-request routing. Orchestration reduces single-vendor concentration; it does not eliminate cloud, policy, supply-chain, or data-governance risk.


Is Fugu-Cyber safer than an unrestricted cyber model?

The release uses three access controls:

  1. An updated Acceptable Usage Policy prohibits offensive misuse.
  2. Applicants must explain their intended use and provide verified contact information.
  3. Sakana manually reviews and approves each request before enabling access.

That is materially stricter than placing a model ID behind an ordinary consumer subscription. It creates identity, declared purpose, and a review checkpoint.

It does not erase the dual-use problem. The skills needed to verify a vulnerability—codebase navigation, reachability analysis, and proof that a flaw triggers—can also help an attacker. CTI-to-detection work is more directly defensive, but threat analysis can still reveal how defenders observe campaigns.

The useful question is therefore not “is the model offensive-capable?” as if capability had a clean binary label. It is: what controls govern who can invoke the capability, against which assets, with what evidence, and under whose approval?

Fugu-Cyber's gated release answers part of that question. Customers must still implement authorization boundaries, repository isolation, secret handling, audit logs, change control, and incident response. An AUP is a policy layer, not a technical proof that misuse cannot occur.


What does Fugu-Cyber cost, and what does “Token Plan” mean?

Sakana's launch announcement says Fugu-Cyber is available on the Token Plan. Its official pricing page describes the model as pay-as-you-go only and lists:

Token typeStandard contextContext above 272K
Input$6 / 1M$12 / 1M
Output$36 / 1M$54 / 1M
Cached input$0.60 / 1M$1.20 / 1M

The listed model ID is fugu-cyber-v1.0. The $20 Standard, $100 Pro, and $200 Max subscriptions cover Fugu and Fugu Ultra, not Fugu-Cyber.

There is one cost detail teams should not miss: orchestration tokens are billable. Sakana reports orchestration input, cached input, and output in token-detail fields, and those tokens count toward the request price. A seemingly concise final answer can therefore represent substantially more internal model work.

That makes cost-per-verified-finding more useful than cost-per-output-token. Compare:

  • total model and orchestration spend;
  • analyst time saved or added;
  • false positives rejected;
  • confirmed issues found;
  • patch regressions avoided;
  • detection rules accepted after production validation.

This is the same economic question raised by Perplexity's GLM 5.2 orchestrator: a coordinated system can cost more tokens while costing less per completed task—if routing and verification actually reduce rework.


Fugu-Cyber vs a single frontier model: which approach wins?

DimensionSingle cyber frontier modelFugu-Cyber orchestrated system
InterfaceOne model endpointOne endpoint that hides multiple agents
Reasoning sourceOne provider/model familyDynamic pool of specialized models
VerificationDepends on the external harnessMulti-agent verification is part of the pitch, with enterprise harnesses layered around it
Vendor concentrationHighReduced, though not eliminated
TransparencyModel ID is known; internals still opaqueUnderlying model selection and topology are not exposed
Latency and tokensUsually fewer coordination stepsPotentially higher fan-out, latency, and billable orchestration
GovernanceVendor's standard cyber policy/tierApplication, verified contact, manual approval, updated AUP
Best caseStrong direct answer with low overheadComplementary agents catch errors and verify multi-step work
Failure modeOne model confidently misses contextSeveral agents amplify a bad premise or add coordination noise

The single-model case is strongest when the task is narrow, the model is already excellent at it, and the organization has a mature harness. Orchestration is strongest when the job decomposes into genuinely different specialties—code analysis, environment validation, threat interpretation, rule generation, and adversarial review.

The burden of proof belongs to the orchestrated system. More agents do not automatically mean more accuracy. They can correlate around the same wrong assumption, increase latency, consume more tokens, and make incident reconstruction harder.


How does this answer the July 2026 cyber-guardrails debate?

The July debate was triggered by reports that Codex and Fable refused defensive security fixes while Kimi K3 and local GLM 5.2 completed them. The specific “15 bugs” count was not independently audited, but the operational complaint was credible: legitimate defenders sometimes need exploit-adjacent reasoning that general hosted products block.

Fugu-Cyber offers a third design:

  • not unrestricted public access, because applicants are identified and reviewed;
  • not a general-model refusal, because the endpoint is purpose-built for cyber defense;
  • not raw permissiveness, because outputs move through specialized verification and human oversight;
  • not one-vendor dependence, because the orchestrator can combine multiple model families.

This is a direct response to defender–attacker asymmetry. Instead of weakening every public guardrail, vendors can create scoped cyber surfaces where identity, intended use, asset authorization, and auditability justify more capable behavior.

Whether Fugu-Cyber gets that balance right cannot be inferred from its AUP or benchmark table. The real test is whether approved blue teams can complete authorized vulnerability and detection workflows with fewer arbitrary refusals without creating a broadly reusable offensive service.


Who should apply for Fugu-Cyber?

Strong candidates:

  • Enterprise AppSec teams with large private codebases and an existing reproduction harness
  • SOC and detection-engineering teams processing high volumes of threat reports
  • Japanese financial institutions and critical-infrastructure operators seeking local implementation support
  • Managed security teams that can isolate customer environments and prove authorization
  • AI-security evaluation groups measuring verified findings, false positives, latency, and analyst effort

Apply only after foundational work:

  • Teams without a software bill of materials, asset inventory, or reproducible builds
  • Organizations that cannot safely expose source code or telemetry to a managed endpoint
  • Security groups with no human capacity to review and retest model output
  • Buyers seeking an autonomous “find and patch everything” button

Poor fit:

  • Offensive operators, malware development, credential theft, or unauthorized scanning—the AUP prohibits misuse
  • Individuals expecting access through the normal Fugu subscription
  • Air-gapped teams that require local weights and full routing transparency; consider the self-hosted defensive model path instead

Before applying, define one bounded evaluation: a sanitized repository with known and unknown issues, or a threat-intelligence set with production-like telemetry. Measure verified recall, false positives, analyst minutes, cost, and safe patch or rule acceptance. Do not procure from CyberGym and CTI-REALM alone.


Bottom line

Fugu-Cyber extends Sakana's orchestration thesis into the domain where orchestration may matter most. Security work is naturally multi-step and adversarial: finding a candidate weakness is only the beginning; verifying reachability, reproducing behavior, understanding production context, proposing a safe fix, and retesting require different kinds of reasoning and evidence.

The 86.9% CyberGym and 72.1% CTI-REALM results make Fugu-Cyber worth evaluating. They do not independently prove parity with GPT-5.5-Cyber or Mythos-Preview, and they do not prove that a private enterprise deployment will be accurate, fast, or economical.

Sakana's strongest argument is more modest and more useful: frontier capability without a localized harness and skilled humans is not operational security. The gated API, Japanese enterprise support, specialized sub-agents, and human-in-the-loop verification are the actual product thesis. The benchmark is the invitation to test it.

Related on explainx.ai

  • Sakana Fugu: one model API to orchestrate all the others
  • The Stack v3 — 5T open code tokens
  • Echo by Tracer — open-weight pool / allocation vs Fugu-style orchestration
  • Sakana's "Diffusing Blame" — Dale's principle and biologically plausible learning
  • Asian AI fills the Mythos gap: Sakana Fugu and sovereign alternatives
  • Hugging Face breach — the full autonomous AI agent incident
  • AI cyber guardrails block defenders: Kimi K3 and local GLM 5.2
  • Claude Mythos Preview and Project Glasswing cybersecurity
  • VulnCheck — AI-found bugs exploit rate (1H 2026)
  • Zhipu matches Mythos on security benchmarks
  • Perplexity's GLM 5.2 orchestrator and the cost-per-task argument
  • OpenAI Daybreak and Codex cyber defense
  • Agent harness engineering for verifiable workflows

Official sources: Sakana AI Fugu-Cyber announcement · Fugu product and API · Fugu technical report, arXiv:2606.21228 · Sakana pricing

Product access, prices, policies, and benchmark claims are accurate as of July 21, 2026. Fugu-Cyber results are vendor-reported; verify capability, false positives, data handling, and total orchestration cost on an authorized workload before production use.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

Jun 22, 2026

Sakana Fugu: One Model API to Orchestrate All the Others

Sakana AI's Fugu Ultra launched June 22 with bold benchmark claims against Fable 5 and Mythos. Within 24 hours, Ethan Mollick and other testers reported 30-minute shader runs, ~$6 per demo, and output that does not match Fable in real use — despite strong published scores. Here is what the Harbor bench reveals.

Jul 27, 2026

Sakana Fugu in Claude Code: Setup, Pricing, and Limits

Sakana AI now exposes Fugu and Fugu-Ultra v1.1 through a Claude Code-compatible interface. This guide shows the one-command and manual setup paths, then explains pricing, routing, privacy, and the compatibility details hidden behind the familiar terminal UI.

Jun 27, 2026

Asian AI fills the Mythos gap: Sakana Fugu, 360 Tulongfeng, and the export-ban vacuum

TechCrunch reports Tokyo's Sakana Fugu and China's 360 Tulongfeng stepping into the space Anthropic left when export controls pulled Mythos offline. We connect the dots across fifteen days of bans, distillation wars, and partial US restores.